| Vuln ID | Summary | CVSS Severity |
|---|---|---|
| CVE-2016-0608 |
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to UDF. Published: January 20, 2016; 10:02:35 PM -0500 |
V3.x:(not available) V2.0: 3.5 LOW |
| CVE-2016-0607 |
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via unknown vectors related to replication. Published: January 20, 2016; 10:02:33 PM -0500 |
V3.x:(not available) V2.0: 2.8 LOW |
| CVE-2016-0606 |
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect integrity via unknown vectors related to encryption. Published: January 20, 2016; 10:02:32 PM -0500 |
V3.x:(not available) V2.0: 3.5 LOW |
| CVE-2016-0605 |
Unspecified vulnerability in Oracle MySQL 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors. Published: January 20, 2016; 10:02:31 PM -0500 |
V3.x:(not available) V2.0: 2.1 LOW |
| CVE-2016-0600 |
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to InnoDB. Published: January 20, 2016; 10:02:28 PM -0500 |
V3.x:(not available) V2.0: 3.5 LOW |
| CVE-2016-0598 |
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to DML. Published: January 20, 2016; 10:02:26 PM -0500 |
V3.x:(not available) V2.0: 3.5 LOW |
| CVE-2016-0597 |
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Optimizer. Published: January 20, 2016; 10:02:25 PM -0500 |
V3.x:(not available) V2.0: 4.0 MEDIUM |
| CVE-2016-0596 |
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and 5.6.27 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to DML. Published: January 20, 2016; 10:02:24 PM -0500 |
V3.x:(not available) V2.0: 4.0 MEDIUM |
| CVE-2016-0595 |
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier allows remote authenticated users to affect availability via vectors related to DML. Published: January 20, 2016; 10:02:23 PM -0500 |
V3.x:(not available) V2.0: 4.0 MEDIUM |
| CVE-2016-0594 |
Unspecified vulnerability in Oracle MySQL 5.6.21 and earlier allows remote authenticated users to affect availability via vectors related to DML. Published: January 20, 2016; 10:02:22 PM -0500 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
| CVE-2016-0546 |
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Client. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that these are multiple buffer overflows in the mysqlshow tool that allow remote database servers to have unspecified impact via a long table or database name. Published: January 20, 2016; 10:01:33 PM -0500 |
V3.x:(not available) V2.0: 7.2 HIGH |
| CVE-2016-0505 |
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Options. Published: January 20, 2016; 10:00:53 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2016-0504 |
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via vectors related to DML, a different vulnerability than CVE-2016-0503. Published: January 20, 2016; 10:00:52 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2016-0503 |
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via vectors related to DML, a different vulnerability than CVE-2016-0504. Published: January 20, 2016; 10:00:51 PM -0500 |
V3.x:(not available) V2.0: 4.0 MEDIUM |
| CVE-2016-0502 |
Unspecified vulnerability in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer. Published: January 20, 2016; 10:00:50 PM -0500 |
V3.x:(not available) V2.0: 4.0 MEDIUM |
| CVE-2016-1494 |
The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof signatures with a small public exponent via crafted signature padding, aka a BERserk attack. Published: January 13, 2016; 10:59:02 AM -0500 |
V3.0: 5.3 MEDIUM V2.0: 5.0 MEDIUM |
| CVE-2015-7575 |
Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision. Published: January 08, 2016; 9:59:10 PM -0500 |
V3.0: 5.9 MEDIUM V2.0: 4.3 MEDIUM |
| CVE-2015-8547 |
The CoreUserInputHandler::doMode function in core/coreuserinputhandler.cpp in Quassel 0.10.0 allows remote attackers to cause a denial of service (application crash) via the "/op *" command in a query. Published: January 08, 2016; 2:59:14 PM -0500 |
V3.0: 7.5 HIGH V2.0: 5.0 MEDIUM |
| CVE-2015-7758 |
Gummi 0.6.5 allows local users to write to arbitrary files via a symlink attack on a temporary dot file that uses the name of an existing file and a (1) .aux, (2) .log, (3) .out, (4) .pdf, or (5) .toc extension for the file name, as demonstrated by .thesis.tex.aux. Published: January 08, 2016; 2:59:09 PM -0500 |
V3.0: 3.3 LOW V2.0: 2.1 LOW |
| CVE-2015-7223 |
The WebExtension APIs in Mozilla Firefox before 43.0 allow remote attackers to gain privileges, and possibly obtain sensitive information or conduct cross-site scripting (XSS) attacks, via a crafted web site. Published: December 16, 2015; 6:59:21 AM -0500 |
V3.x:(not available) V2.0: 4.0 MEDIUM |